CVE-2015-2296

Severity

68%

Complexity

86%

Confidentiality

106%

CWE-384: Session Fixation

The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.

CWE-384: Session Fixation

CVSS 2.0 Base Score 6.8. CVSS Attack Vector: network. CVSS Attack Complexity: medium. CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).

Overview

First reported 9 years ago

2015-03-18 16:59:00

Last updated 8 years ago

2016-07-15 15:23:00

Affected Software

Python-Requests Requests 2.1.0

2.1.0

Python-Requests Requests 2.2.1

2.2.1

Python-Requests Requests 2.3.0

2.3.0

Python-Requests Requests 2.4.0

2.4.0

Python-Requests Requests 2.4.1

2.4.1

Python-Requests Requests 2.4.2

2.4.2

Python-Requests Requests 2.4.3

2.4.3

Python-Requests Requests 2.5.0

2.5.0

Python-Requests Requests 2.5.1

2.5.1

Python-Requests Requests 2.5.2

2.5.2

Python-Requests Requests 2.5.3

2.5.3

Canonical Ubuntu Linux 14.04 LTS (Long-Term Support)

14.04

Canonical Ubuntu Linux 14.10

14.10

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.